testing-end-user
Warn
Audited by Socket on Mar 18, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the stated purpose is coherent for a testing skill, but its footprint is broad because it converts user/project-authored task content directly into shell execution against real infrastructure. There is no clear credential-harvesting or malicious exfiltration path in the provided text, yet the combination of arbitrary command execution, external network reach, file/log access, and untrusted task parsing makes it a high-risk operational skill rather than a benign narrow verifier.
Confidence: 86%Severity: 74%
Audit Metadata